Incident Oracle E-Business Suite Clop data-breach Oracle malware
Estée Lauder discloses data breach via Oracle E-Business flaw
CVE Tools coverage
Cosmetics giant Estée Lauder has disclosed a data breach following an attack that exploited a vulnerability in Oracle E-Business Suite (CVE-2025-61882). Hackers gained unauthorized access on August 9, 2025, stealing personal details such as full names, Social Security numbers, health records, and financial account information. The flaw allowed remote code execution and was actively exploited by the Clop ransomware group since early 2025. Oracle issued patches for the issue in October 2025, but the breach highlights ongoing risks for organizations using unpatched systems.